Skip to content
  • About
  • Contact
  • Contribute
  • Book
  • Careers
  • Podcast
  • Recommended
  • Speaking
KevinMD
  • All
  • Physician
  • Practice
  • Policy
  • Finance
  • Conditions
  • .edu
  • Patient
  • Meds
  • Tech
  • Social
  • Video
  • All
  • Physician
  • Practice
  • Policy
  • Finance
  • Conditions
  • .edu
  • Patient
  • Meds
  • Tech
  • Social
  • Video
    • All
    • Physician
    • Practice
    • Policy
    • Finance
    • Conditions
    • .edu
    • Patient
    • Meds
    • Tech
    • Social
    • Video
    • About
    • Contact
    • Contribute
    • Book
    • Careers
    • Podcast
    • Recommended
    • Speaking
KevinMD
  • All
  • Physician
  • Practice
  • Policy
  • Finance
  • Conditions
  • .edu
  • Patient
  • Meds
  • Tech
  • Social
  • Video
    • All
    • Physician
    • Practice
    • Policy
    • Finance
    • Conditions
    • .edu
    • Patient
    • Meds
    • Tech
    • Social
    • Video
    • About
    • Contact
    • Contribute
    • Book
    • Careers
    • Podcast
    • Recommended
    • Speaking
  • About KevinMD | Kevin Pho, MD
  • Be heard on social media’s leading physician voice
  • Contact Kevin
  • Discounted enhanced author page
  • DMCA Policy
  • Establishing, Managing, and Protecting Your Online Reputation: A Social Media Guide for Physicians and Medical Practices
  • Group vs. individual disability insurance for doctors: pros and cons
  • KevinMD influencer opportunities
  • Opinion and commentary by KevinMD
  • Physician burnout speakers to keynote your conference
  • Physician Coaching by KevinMD
  • Physician keynote speaker: Kevin Pho, MD
  • Physician Speaking by KevinMD: a boutique speakers bureau
  • Primary care physician in Nashua, NH | Kevin Pho, MD
  • Privacy Policy
  • Recommended services by KevinMD
  • Terms of Use Agreement
  • Thank you for subscribing to KevinMD
  • Thank you for upgrading to the KevinMD enhanced author page
  • The biggest mistake doctors make when purchasing disability insurance
  • The doctor’s guide to disability insurance: short-term vs. long-term
  • The KevinMD ToolKit
  • Upgrade to the KevinMD enhanced author page
  • Why own-occupation disability insurance is a must for doctors

Protecting health apps on the web from the evils of the Internet

John Halamka, MD
Tech
October 3, 2011
Share
Tweet
Share

The Internet can be a swamp of hackers, crackers, and hucksters attacking your systems for fun, profit and fraud.  Defending your data and applications against this onslaught is a cold war, requiring constant escalation of new techniques against an ever increasing offense.

Clinicians are mobile people.  They work in ambulatory offices, hospitals, skilled nursing facilities, on the road, and at home.   They have desktops, laptops, tablets, iPhones and iPads.  Ideally their applications should run everywhere on everything.   That’s the reason we’ve embraced the web for all our built and bought applications.   Protecting these web applications from the evils of the Internet is a challenge.

Five years ago all of our externally facing web sites were housed within the data center and made available via network address translation (NAT)  through an opening in the firewall.   We performed periodic penetration testing of our sites.  Two years ago, we installed a Web Application Firewall (WAF) and proxy system.    We are now in the process of migrating all of our web applications from NAT/firewall accessibility to WAF/Proxy accessibility.

We have a few hundred externally facing web sites.  From a security view there are only two types, those that provide access to protected health information content and those that do not.   Fortunately more are in the latter than the former.

One of the major motivations for creating a multi-layered defense was the realization that many vendor products are vulnerable and even when problems are identified, vendors can be slow to correct defects.   We need  “zero day protection” to secure purchased applications against evolving threats.

Technologies to include in a multi-layered defense include:

1.  Filter out basic network probes at the border router such as traffic on unused ports

2.  Use Intrusion Prevention Systems (IPS)  to block common attacks such as SQL Injection and cross site scripting. We block over 10,000 such attacks per day.   You could implement multiple IPSs from different vendors to create a suite of features including URL filtering  which prevent internal users from accessing known malware sites.

3.  A classic firewall and Demilitarized Zone (DMZ)  to limit the “attack surface“.

Policies and procedures are an important aspect of maintaining a secure environment.   When a request is made to host a new application, we start with a Nessus vulnerability scan.

Applications must pass the scan before we will consider hosting them.   We built a simple online request form for these requests for access to both track the requests and keep the data a SQL data base.    This provides the data source for an automated re-scan of each system.

Penetration testing of internally written applications is a bit more valuable because they are easier to update/correct based on the findings of penetration tests.

One caveat.   The quality of penetration testing is highly variable.    When we hire firms to attack our applications, we often get a report filled with theoretical risks that are not especially helpful i.e. if your web server was accidentally configured to accept HTTP connections instead of forced HTTPS connections, the application would be vulnerable.   That’s true and if a meteor struck our data center, we would have many challenges on our hands.  When choosing a penetration testing vendor, aim for one that can put their findings in a real world context.

Thus, our mitigation strategy is to apply deep wire based security, utilize many tools including IPS, traditional firewalls, WAF and proxy servers, and perform periodic re-occurring internal scans of all systems that are available externally to our network.

Of course, all of this takes a team of trained professionals.

I hope this is helpful for your own security planning.

John Halamka is Chief Information Officer of Beth Israel Deaconess Medical Center and blogs at Life as a Healthcare CIO.

Submit a guest post and be heard on social media’s leading physician voice.

Prev

Lawsuits are more of an emotional issue than a financial one

October 3, 2011 Kevin 7
…
Next

Universal board certification can solve the Doctor Nurse controversy

October 3, 2011 Kevin 18
…

Tagged as: Health IT

< Previous Post
Lawsuits are more of an emotional issue than a financial one
Next Post >
Universal board certification can solve the Doctor Nurse controversy

ADVERTISEMENT

More by John Halamka, MD

  • The future of EHR: Here are 5 predictions

    John Halamka, MD
  • 10 crucial guidelines for health care IT

    John Halamka, MD
  • 5 health care IT tips for President Trump

    John Halamka, MD

More in Tech

  • AI agents in health care: What they say when we aren’t listening

    Alp Köksal
  • The hidden risks and rewards of AI scribes in medicine

    Arthur Lazarus, MD, MBA
  • The hidden risks of AI-generated progress notes in psychotherapy

    Arthur Lazarus, MD, MBA
  • How AI in dentistry is changing your next checkup

    Sowjanya Gunukula, DDS
  • Early-stage medical device innovation: How to discuss untested ideas

    Jarelis Cabrera
  • AI in health care data management: Curing the EHR overload

    Hamad Husainy, DO
  • Most Popular

  • Past Week

    • The dangers of vertical integration in health care

      Stephanie Waggel, MD | Policy
    • The 9 laws of health care quality: Why metrics miss the point

      Constantine Ioannou, MD | Physician
    • Navigating the patchwork of CME requirements by state

      Vladislav Tchatalbachev, MD | Physician
    • Securing physician autonomy with employer-sponsored direct primary care

      Dana Y. Lujan, MBA | Physician
    • Adult disability care transition: Why medicine must grow up

      Ronald L. Lindsay, MD | Conditions
    • Chronic pain management: Balancing relief and regulation

      Kayvan Haddadan, MD | Physician
  • Past 6 Months

    • Missed diagnosis visceral leishmaniasis: a tragedy of note bloat

      Arthur Lazarus, MD, MBA | Conditions
    • Menstrual health in medicine: Addressing the gender gap in care

      Cynthia Kumaran | Conditions
    • The dangers of vertical integration in health care

      Stephanie Waggel, MD | Policy
    • The 9 laws of health care quality: Why metrics miss the point

      Constantine Ioannou, MD | Physician
    • Why does sex work seem like a more viable path than medicine in 2026?

      Corina Fratila, MD | Physician
    • How board certification fuels the physician shortage crisis

      Brian Hudes, MD | Physician
  • Recent Posts

    • Chronic pain management: Balancing relief and regulation

      Kayvan Haddadan, MD | Physician
    • Why modern medicine feels more like a bureaucracy than a profession

      Jeffrey Junig, MD, PhD | Physician
    • AI agents in health care: What they say when we aren’t listening

      Alp Köksal | Tech
    • Huntington’s disease gene therapy: FDA reversal delays AMT-130

      Meghan Johnston, MPH | Meds
    • Emergency nurses struggle to turn off survival mode after the pandemic [PODCAST]

      The Podcast by KevinMD | Podcast
    • Why perfectionism in medicine leads to moral injury

      Farid Sabet-Sharghi, MD | Conditions

Subscribe to KevinMD and never miss a story!

Get free updates delivered free to your inbox.


Find jobs at
Careers by KevinMD.com

Search thousands of physician, PA, NP, and CRNA jobs now.

Learn more

Leave a Comment

Founded in 2004 by Kevin Pho, MD, KevinMD.com is the web’s leading platform where physicians, advanced practitioners, nurses, medical students, and patients share their insight and tell their stories.

Social

  • Like on Facebook
  • Follow on Twitter
  • Connect on Linkedin
  • Subscribe on Youtube
  • Instagram

ADVERTISEMENT

  • Most Popular

  • Past Week

    • The dangers of vertical integration in health care

      Stephanie Waggel, MD | Policy
    • The 9 laws of health care quality: Why metrics miss the point

      Constantine Ioannou, MD | Physician
    • Navigating the patchwork of CME requirements by state

      Vladislav Tchatalbachev, MD | Physician
    • Securing physician autonomy with employer-sponsored direct primary care

      Dana Y. Lujan, MBA | Physician
    • Adult disability care transition: Why medicine must grow up

      Ronald L. Lindsay, MD | Conditions
    • Chronic pain management: Balancing relief and regulation

      Kayvan Haddadan, MD | Physician
  • Past 6 Months

    • Missed diagnosis visceral leishmaniasis: a tragedy of note bloat

      Arthur Lazarus, MD, MBA | Conditions
    • Menstrual health in medicine: Addressing the gender gap in care

      Cynthia Kumaran | Conditions
    • The dangers of vertical integration in health care

      Stephanie Waggel, MD | Policy
    • The 9 laws of health care quality: Why metrics miss the point

      Constantine Ioannou, MD | Physician
    • Why does sex work seem like a more viable path than medicine in 2026?

      Corina Fratila, MD | Physician
    • How board certification fuels the physician shortage crisis

      Brian Hudes, MD | Physician
  • Recent Posts

    • Chronic pain management: Balancing relief and regulation

      Kayvan Haddadan, MD | Physician
    • Why modern medicine feels more like a bureaucracy than a profession

      Jeffrey Junig, MD, PhD | Physician
    • AI agents in health care: What they say when we aren’t listening

      Alp Köksal | Tech
    • Huntington’s disease gene therapy: FDA reversal delays AMT-130

      Meghan Johnston, MPH | Meds
    • Emergency nurses struggle to turn off survival mode after the pandemic [PODCAST]

      The Podcast by KevinMD | Podcast
    • Why perfectionism in medicine leads to moral injury

      Farid Sabet-Sharghi, MD | Conditions

MedPage Today Professional

An Everyday Health Property Medpage Today

Copyright © 2026 KevinMD.com | Powered by Astra WordPress Theme

  • Terms of Use | Disclaimer
  • Privacy Policy
  • DMCA Policy
All Content © KevinMD, LLC
Site by Outthink Group

Leave a Comment

Comments are moderated before they are published. Please read the comment policy.

Loading Comments...